Wind River Support Network

HomeDefectsLIN1021-7895
Fixed

LIN1021-7895 : Security Advisory - linux - CVE-2023-52626

Created: Mar 26, 2024    Updated: May 31, 2024
Resolved Date: May 31, 2024
Found In Version: 10.21.20.1
Fix Version: 10.21.20.21
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context

Indirection (*) is of lower precedence than postfix increment (++). Logic
in napi_poll context would cause an out-of-bound read by first increment
the pointer address by byte address space and then dereference the value.
Rather, the intended logic was to dereference first and then increment the
underlying value.

CREATE(Triage):(User=admin) CVE-2023-52626 (https://nvd.nist.gov/vuln/detail/CVE-2023-52626)

CVEs


Live chat
Online